350-401 Virtualization Practice Question
An engineer is configuring a Cisco Nexus 9000 switch running VXLAN EVPN. Tenant traffic must be encapsulated with a VXLAN header that includes a 24-bit VNI, and the underlay must provide loopback-based VTEP addressing with ECMP. The engineer notices that the switch is not forming VXLAN tunnels to remote leaf switches. Which configuration issue is the most likely cause?
⚠ Common exam trap
The trap here is blaming the underlay routing protocol or VNI bit width, when the actual prerequisite for tunnel formation is a valid NVE source interface and complete VNI-to-VLAN mappings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The NVE interface is missing the source-interface loopback and the VNI-to-VLAN mapping is incomplete
VXLAN tunnel formation on a Nexus 9000 requires the NVE interface to have a source-interface, usually a loopback, and correct VNI-to-VLAN mappings. Without a valid VTEP source address or with incomplete VNI mappings, the switch cannot establish tunnels to remote leaf VTEPs, which matches the observed failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switch is using a 12-bit VLAN ID instead of the required 24-bit VNI in the VXLAN header
Why it's wrong here
VLAN IDs are 12-bit and VNIs are 24-bit, but the VXLAN header always carries the VNI, not the VLAN ID. The mapping between VLAN and VNI is configured under the NVE interface, so this is not a plausible cause of tunnel failure. The absence of tunnel formation points to VTEP or NVE configuration rather than header field size confusion.
- ✓
The NVE interface is missing the source-interface loopback and the VNI-to-VLAN mapping is incomplete
Why this is correct
The NVE interface requires a source-interface, typically a loopback, to establish the VTEP address used in VXLAN tunnels. If the source interface is missing or the VNI-to-VLAN mapping under the NVE interface is incomplete, the switch cannot build tunnels or map traffic into VNIs. This directly explains why VXLAN tunnels to remote leaf switches are not forming in the scenario.
- ✗
The underlay is running OSPF instead of BGP, which prevents VXLAN tunnel establishment
Why it's wrong here
VXLAN encapsulation does not depend on a specific underlay routing protocol. OSPF can provide loopback reachability and ECMP just as BGP can, and VXLAN tunnels can form over either. The EVPN control plane typically uses BGP, but the data-plane VXLAN tunnels themselves only require IP reachability between VTEP loopbacks, so the underlay protocol choice is not the cause.
- ✗
The switch is configured with VXLAN VNI 16777216, which exceeds the 24-bit range
Why it's wrong here
A 24-bit VNI ranges from 0 to 16777215, so a value of 16777216 would indeed be invalid. However, NX-OS would reject such a configuration at commit time, and the scenario describes tunnels not forming rather than an invalid VNI error. The more likely operational cause is a missing NVE source interface or incomplete VNI-to-VLAN mapping.
Visual reference
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.